Privacy Policy
1. Who we are
Members Health Co is a healthcare practice based in Nashville, Tennessee. When this Privacy Policy says “Members Health Co,” “we,” “us,” or “our,” we mean Members Health Co and the individuals authorized to act on our behalf.
2. Scope of this Privacy Policy
This Privacy Policy applies to information we collect through:
- Our marketing website at membershealthco.com.
- Our Patient Portal at portal.membershealthco.com, with respect to information that is not PHI under HIPAA.
- Other channels we operate from time to time (e.g., email communications about your relationship with us, with respect to information that is not PHI).
Not in scope:
- PHI as defined by HIPAA, which is governed by our Notice of Privacy Practices.
- Information collected by third-party services (e.g., a booking platform we link to) when you use those services directly; their own privacy policies apply.
3. Information we collect
3.1 Information you provide to us
- Contact information such as name, email, phone number, and mailing address when you become or remain a patient or when you contact us.
- Communications you send us through email when you contact us about a non-medical matter.
- Patient information that we collect in the course of providing healthcare. This information is PHI and is governed by our Notice of Privacy Practices, not this Privacy Policy.
3.2 Information collected automatically
When you visit the marketing website at membershealthco.com:
- Our website is hosted on Squarespace. Squarespace collects basic first-party analytics including page views and approximate geographic origin (city or region inferred from IP).
- We do not load the Meta (Facebook) Pixel, Google Analytics, Google Tag Manager, or other third-party tracking or advertising pixels on the marketing website.
- We do not load session-replay tools (e.g., Hotjar, FullStory) on the marketing website.
When you use the Patient Portal at portal.membershealthco.com:
- We log your authentication events (sign-in, sign-out, failed sign-in attempts) including the date and time, the email or phone number used, and the IP address.
- We log your activity within the Portal (which pages you view) as part of the audit trail required by HIPAA. This audit information is PHI to the extent it pertains to your healthcare and is governed by our Notice of Privacy Practices.
- We set first-party cookies on the Portal that hold your encrypted session identifier so you do not have to sign in repeatedly. The patient session cookie expires 24 hours after it is issued; the staff session cookie (used by clinic team members) expires 8 hours after it is issued. We do not place advertising cookies on the Portal. See our Cookie Policy for the full list.
- We do not load third-party analytics, advertising pixels, session-replay tools, or chat widgets on any page of the Portal where your health information is or could be visible.
- On the sign-in page only, when you request a one-time code sent by SMS, we load Google’s reCAPTCHA Enterprise service. reCAPTCHA is a fraud-prevention tool that helps prevent automated abuse of the SMS-sending system; it is required by the Google service that delivers our sign-in codes. reCAPTCHA runs only on the sign-in page (where no health information is shown) and only during the SMS-sign-in flow. Google’s use of any data collected by reCAPTCHA is governed by Google’s terms; we have a Business Associate Agreement with Google for healthcare-data services.
4. How we use information
We use the information we collect to:
- Operate, maintain, and improve our website and Patient Portal.
- Authenticate you to the Patient Portal and protect the security of your account.
- Respond to your inquiries.
- Send you communications related to your relationship with us as a patient or prospective patient.
- Comply with our legal obligations, including audit and breach-notification obligations under HIPAA and applicable state law.
- Detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms of Service.
What we do not do:
- We do not sell your personal information.
- We do not share your personal information with third parties for cross-context behavioral advertising or targeted advertising.
- We do not use your personal information to train artificial-intelligence models, except to the extent that internal use of de-identified analytics may inform our clinical workflows under our HIPAA program.
5. How we share information
We may share information in the following circumstances:
- Service providers and business associates. We use vendors to operate our website, Patient Portal, and other systems. Where these vendors handle PHI on our behalf, we maintain Business Associate Agreements with them as required by HIPAA. Vendors that handle non-PHI personal information (such as our website host) are bound by their own privacy obligations.
- Legal compliance. We may disclose information when we believe in good faith that disclosure is required by law, legal process, or to protect the rights, property, or safety of Members Health Co, our patients, or others.
- Business changes. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to the protections of this Privacy Policy and applicable law.
- With your consent. We may share information with your consent or at your direction.
6. How we store and protect information
We use a combination of administrative, technical, and physical safeguards to protect information against loss, theft, and unauthorized access. These include encryption of data at rest in our database, encryption in transit using TLS, access controls limiting who at Members Health Co can view which records, audit logging, and workforce training. No method of transmission or storage is perfectly secure, however, and we cannot guarantee the absolute security of any information.
7. Your privacy rights — general
Depending on where you live, you may have rights regarding your personal information. We honor these rights as required by applicable law:
- Right to know / access. You may request a copy of the personal information we hold about you.
- Right to correct. You may request that we correct personal information you believe is inaccurate.
- Right to delete. You may request that we delete personal information we hold about you, subject to exceptions for information we are required to retain under law (including HIPAA records-retention obligations).
- Right to opt out. Where applicable, you may opt out of certain uses of your personal information.
To make a request, contact us using the information in Section 12. We will verify your identity before fulfilling a request, and we will respond within the timeframe required by applicable law.
8. State-specific privacy rights
8.1 Tennessee residents
The Tennessee Information Protection Act (“TIPA,” Tenn. Code Ann. §47-18-3201 et seq.) gives Tennessee residents rights regarding their personal information. To the extent TIPA applies to information we hold about you (subject to TIPA’s HIPAA-related exemptions), you have the right to confirm whether we are processing your personal information, to access it, to correct inaccuracies, to delete it (subject to retention obligations), and to obtain a portable copy. To exercise your TIPA rights, contact us using the information in Section 12. If we deny your request, you may appeal by following the same contact procedure.
8.2 Washington residents
The Washington My Health My Data Act (“WMHMDA,” RCW 19.373) gives Washington residents rights regarding consumer health data. To the extent WMHMDA applies to information we hold about you (subject to WMHMDA’s HIPAA-related exemptions for protected health information), you have the right to confirm whether we collect, share, or sell your consumer health data; to access it; to withdraw consent; and to have it deleted. We do not sell consumer health data.
8.3 California residents
Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), and the Confidentiality of Medical Information Act (“CMIA,” Cal. Civ. Code §56 et seq.), California residents have rights regarding personal information and medical information. Our handling of medical information about California residents is governed primarily by CMIA and HIPAA. Categories of personal information we may collect from California residents about non-medical interactions include identifiers (name, email, phone), internet activity (IP address and Portal sign-in events), and inferences drawn from the foregoing.
- We do not sell or share personal information for cross-context behavioral advertising.
- California residents may exercise the right to know, the right to delete, the right to correct, and the right to limit use of sensitive personal information. We do not use sensitive personal information for purposes beyond those permitted under CCPA §7027(m).
8.4 Other states
If you are a resident of another state with a comprehensive privacy law (Virginia, Colorado, Connecticut, Utah, Texas, or others), we honor the rights granted by your state’s law to the extent it applies to information we hold about you. Contact us using the information in Section 12 to exercise those rights.
9. Children
Our website and Patient Portal are not directed to children under 18. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from someone under 18, we will delete it. If you believe we may have collected information from a child under 18, contact us using the information in Section 12.
10. Information for residents outside the United States
Members Health Co operates in the United States. If you visit our website or use our Patient Portal from outside the United States, information we collect will be transferred to and processed in the United States. By using our services, you understand that your information will be processed in the United States, which may have data protection rules different from those of your country.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date above and, if the changes are material, provide additional notice (such as a notice on our website or by email). Your continued use of our website or Patient Portal after the changes become effective constitutes acceptance of the updated Privacy Policy.
12. How to contact us
To exercise your privacy rights, ask questions about this Privacy Policy, or report a privacy concern, contact us at:
Members Health Co
Attn: Privacy Officer
705 Merritt Ave, Nashville, TN 37203
(615) 601-3600
info@membershealthco.com